Skip to main content
QUICK REVIEW

[Paper Review] Time Stamp Attack in Smart Grid: Physical Mechanism and Damage Analysis

Shuping Gong, Zhenghao Zhang|arXiv (Cornell University)|Jan 12, 2012
Power Systems Fault Detection12 references16 citations
TL;DR

This paper proposes a novel Time Stamp Attack (TSA) exploiting GPS spoofing to corrupt timing information in smart grid wide area monitoring systems (WAMS), undermining PMU-based applications like fault detection, voltage stability monitoring, and event locationing. By forging GPS signals with higher SNR, attackers manipulate time stamps, causing significant performance degradation and false operations in critical grid functions.

ABSTRACT

Many operations in power grids, such as fault detection and event location estimation, depend on precise timing information. In this paper, a novel time stamp attack (TSA) is proposed to attack the timing information in smart grid. Since many applications in smart grid utilize synchronous measurements and most of the measurement devices are equipped with global positioning system (GPS) for precise timing, it is highly probable to attack the measurement system by spoofing the GPS. The effectiveness of TSA is demonstrated for three applications of phasor measurement unit (PMU) in smart grid, namely transmission line fault detection, voltage stability monitoring and event locationing.

Motivation & Objective

  • To identify a previously unaddressed physical-layer cyberattack—Time Stamp Attack (TSA)—that compromises timing integrity in smart grid WAMS.
  • To analyze the physical mechanism of GPS spoofing that enables TSA by exploiting the signal-to-noise ratio (SNR) advantage of forged signals over genuine GPS signals.
  • To evaluate the impact of TSA on three key PMU applications: transmission line fault detection/locationing, voltage stability monitoring, and regional disturbance event locationing.
  • To demonstrate that TSA can bypass traditional data filtering and integrity checks by corrupting time stamps rather than measurement values.
  • To provide a foundation for future detection and protection mechanisms against such timing-based cyber threats in power systems.

Proposed method

  • Modeling GPS signal acquisition and tracking processes, focusing on correlation peak detection in code phase and carrier frequency space to identify spoofing vulnerabilities.
  • Designing a spoofing attack model where a forged GPS signal with higher SNR than the authentic signal is transmitted to mislead GPS receivers into locking onto the fake signal.
  • Using the coordinated universal time (UTC) equation $ t_{UTC} = t_{rcv} - t_p - \Delta t_{UTC} $ to model time stamp generation and corruption under spoofing.
  • Simulating TSA effects on PMU applications using a synchronized phasor measurement framework with controlled time offset ($\Delta\theta$) to represent asynchronism.
  • Applying fault indicators $N$ and $M$, power margin index $\text{MARGIN}_P$, and event location estimation algorithms to quantify performance degradation under TSA.
  • Employing SNR and direction-of-arrival (DOA) discrimination as potential detection methods for TSA, based on the physical characteristics of spoofed signals.

Experimental results

Research questions

  • RQ1How can GPS spoofing be leveraged to manipulate time stamps in smart grid monitoring systems without compromising data integrity?
  • RQ2To what extent does TSA degrade the performance of PMU-based transmission line fault detection and locationing algorithms?
  • RQ3How does TSA affect voltage stability monitoring, particularly in terms of false power margin estimation and alarm delay?
  • RQ4What is the impact of TSA on regional disturbance event locationing, and how does it mislead the estimated event origin?
  • RQ5Can TSA be detected using signal processing techniques such as SNR analysis or DOA discrimination?

Key findings

  • TSA successfully corrupts time stamps by spoofing GPS signals with higher SNR, causing GPS receivers to lock onto forged signals and misalign measurement timestamps.
  • For long transmission lines, fault locationing error increases proportionally with phase angle asynchronism $\Delta\theta$, reaching up to 0.2 when $\Delta\theta = 30^\circ$ and fault index $D = 0.5$ or $0.75$.
  • Voltage stability monitoring is significantly impaired: the estimated power margin index $\widehat{\text{MARGIN}_P}$ shows increasing error with $|\Delta\theta|$, and the error growth is asymmetric—faster for positive $\Delta\theta$.
  • Event locationing is severely compromised; with one MMR under TSA, a true disturbance in Mississippi is mislocated in Tennessee due to time stamp corruption.
  • TSA can increase false alarm probability in fault detection and degrade fault location accuracy, especially under high asynchronism or unbalanced fault types (e.g., Phase A or AB faults).
  • The attack bypasses conventional data filtering and integrity checks because it targets time stamps rather than measurement data, making it stealthy and hard to detect.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.